Sungrow WiNet-S Hardcoded Password Vulnerability Allowing Firmware Decryption
Vulnerability
A vulnerability exists in Sungrow WiNet-S version WINET-SV200.001.00.P027 and earlier, due to a hardcoded password in the WiNet WebUI. This password can be used to decrypt firmware update files, which are otherwise encrypted. The presence of this hardcoded password could potentially be exploited to manipulate the firmware update process.
Impact
Exploitation of this vulnerability allows for unauthorized decryption of firmware update files, which could lead to further manipulation or exploitation of the device.
Remediation
Users are advised to upgrade to WiNet-S version WINET-SV200.001.00.P028 or higher.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
7.4remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
